Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. I'm Going To Take A Hostage

I'm Going To Take A Hostage

Scheduled Pinned Locked Moved The Lounge
securitycode-review
31 Posts 22 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M Offline
    M Offline
    MadGerbil
    wrote on last edited by
    #1

    My credit union forced me to change my password but won't let me use a previous password. I don't know why I get irrationally angry over this - I guess I feel passwords are kind of personal and telling me that I cannot use an old one doesn't improve security at all and seems invasive. If I write insecure passwords changing guest1 to guest2 isn't an improvement. If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement. There is more B.S. superstition around password management than I can handle. One of the most boogered things in all of IT are password management systems. If you write a password management system and force people to change passwords every 30 days YOU ARE A BAD PERSON IN REAL LIFE. Because of this I need to take a hostage. I hope she's cute. :D

    W C S S Mike HankeyM 13 Replies Last reply
    0
    • M MadGerbil

      My credit union forced me to change my password but won't let me use a previous password. I don't know why I get irrationally angry over this - I guess I feel passwords are kind of personal and telling me that I cannot use an old one doesn't improve security at all and seems invasive. If I write insecure passwords changing guest1 to guest2 isn't an improvement. If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement. There is more B.S. superstition around password management than I can handle. One of the most boogered things in all of IT are password management systems. If you write a password management system and force people to change passwords every 30 days YOU ARE A BAD PERSON IN REAL LIFE. Because of this I need to take a hostage. I hope she's cute. :D

      W Offline
      W Offline
      W Balboos GHB
      wrote on last edited by
      #2

      Their is a simple solution to your problem. Please log in for further information. "SWORDFISH"

      Ravings en masse^

      "The difference between genius and stupidity is that genius has its limits." - Albert Einstein

      "If you are searching for perfection in others, then you seek disappointment. If you seek perfection in yourself, then you will find failure." - Balboos HaGadol Mar 2010

      1 Reply Last reply
      0
      • M MadGerbil

        My credit union forced me to change my password but won't let me use a previous password. I don't know why I get irrationally angry over this - I guess I feel passwords are kind of personal and telling me that I cannot use an old one doesn't improve security at all and seems invasive. If I write insecure passwords changing guest1 to guest2 isn't an improvement. If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement. There is more B.S. superstition around password management than I can handle. One of the most boogered things in all of IT are password management systems. If you write a password management system and force people to change passwords every 30 days YOU ARE A BAD PERSON IN REAL LIFE. Because of this I need to take a hostage. I hope she's cute. :D

        C Offline
        C Offline
        CPallini
        wrote on last edited by
        #3

        Quote:

        If you write a password management system and force people to change passwords every 30 days YOU ARE A BAD PERSON IN REAL LIFE.

        :thumbsup: I completely agree!

        L 1 Reply Last reply
        0
        • M MadGerbil

          My credit union forced me to change my password but won't let me use a previous password. I don't know why I get irrationally angry over this - I guess I feel passwords are kind of personal and telling me that I cannot use an old one doesn't improve security at all and seems invasive. If I write insecure passwords changing guest1 to guest2 isn't an improvement. If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement. There is more B.S. superstition around password management than I can handle. One of the most boogered things in all of IT are password management systems. If you write a password management system and force people to change passwords every 30 days YOU ARE A BAD PERSON IN REAL LIFE. Because of this I need to take a hostage. I hope she's cute. :D

          S Offline
          S Offline
          Super Lloyd
          wrote on last edited by
          #4

          I too particularly despise this policy! :O :( :mad::~ That sure must have been a [true password story](https://letvent.com/2014/05/09/creating-a-password-boiled-cabbage/), somehow!

          A new .NET Serializer All in one Menu-Ribbon Bar Taking over the world since 1371!

          1 Reply Last reply
          0
          • M MadGerbil

            My credit union forced me to change my password but won't let me use a previous password. I don't know why I get irrationally angry over this - I guess I feel passwords are kind of personal and telling me that I cannot use an old one doesn't improve security at all and seems invasive. If I write insecure passwords changing guest1 to guest2 isn't an improvement. If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement. There is more B.S. superstition around password management than I can handle. One of the most boogered things in all of IT are password management systems. If you write a password management system and force people to change passwords every 30 days YOU ARE A BAD PERSON IN REAL LIFE. Because of this I need to take a hostage. I hope she's cute. :D

            S Offline
            S Offline
            Slacker007
            wrote on last edited by
            #5

            MadGerbil wrote:

            If you write a password management system and force people to change passwords every 30 days

            this is because if your password is compromised and I have it, then I have only 30 days to use it, before I can't anymore. Not so great for you and the company during those 30 days, but it is better than nothing, I guess. It is a valid level of security. You should be more than glad they don't make you change your password every week. And no, they are not bad people for doing this. No more as bad as the doctor who tells you to quit smoking. I agree it is frustrating, very much so.

            Kornfeld Eliyahu PeterK M G U B 5 Replies Last reply
            0
            • C CPallini

              Quote:

              If you write a password management system and force people to change passwords every 30 days YOU ARE A BAD PERSON IN REAL LIFE.

              :thumbsup: I completely agree!

              L Offline
              L Offline
              Lost User
              wrote on last edited by
              #6

              Agree. Ten days should be the absolute maximum :laugh:

              It does not solve my Problem, but it answers my question

              1 Reply Last reply
              0
              • M MadGerbil

                My credit union forced me to change my password but won't let me use a previous password. I don't know why I get irrationally angry over this - I guess I feel passwords are kind of personal and telling me that I cannot use an old one doesn't improve security at all and seems invasive. If I write insecure passwords changing guest1 to guest2 isn't an improvement. If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement. There is more B.S. superstition around password management than I can handle. One of the most boogered things in all of IT are password management systems. If you write a password management system and force people to change passwords every 30 days YOU ARE A BAD PERSON IN REAL LIFE. Because of this I need to take a hostage. I hope she's cute. :D

                Mike HankeyM Offline
                Mike HankeyM Offline
                Mike Hankey
                wrote on last edited by
                #7

                MadGerbil wrote:

                Because of this I need to take a hostage.

                If you have foul play in mind, I have a list! :)

                I'm not sure how many cookies it makes to be happy, but so far it's not 27. JaxCoder.com

                W 1 Reply Last reply
                0
                • S Slacker007

                  MadGerbil wrote:

                  If you write a password management system and force people to change passwords every 30 days

                  this is because if your password is compromised and I have it, then I have only 30 days to use it, before I can't anymore. Not so great for you and the company during those 30 days, but it is better than nothing, I guess. It is a valid level of security. You should be more than glad they don't make you change your password every week. And no, they are not bad people for doing this. No more as bad as the doctor who tells you to quit smoking. I agree it is frustrating, very much so.

                  Kornfeld Eliyahu PeterK Offline
                  Kornfeld Eliyahu PeterK Offline
                  Kornfeld Eliyahu Peter
                  wrote on last edited by
                  #8

                  The only way my password can be compromised is by mind-reading... Or I give it away... So the site (that obviously does not store it :laugh:) has no reason to be so hard on me...

                  "The only place where Success comes before Work is in the dictionary." Vidal Sassoon, 1928 - 2012

                  "It never ceases to amaze me that a spacecraft launched in 1977 can be fixed remotely from Earth." ― Brian Cox

                  1 Reply Last reply
                  0
                  • M MadGerbil

                    My credit union forced me to change my password but won't let me use a previous password. I don't know why I get irrationally angry over this - I guess I feel passwords are kind of personal and telling me that I cannot use an old one doesn't improve security at all and seems invasive. If I write insecure passwords changing guest1 to guest2 isn't an improvement. If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement. There is more B.S. superstition around password management than I can handle. One of the most boogered things in all of IT are password management systems. If you write a password management system and force people to change passwords every 30 days YOU ARE A BAD PERSON IN REAL LIFE. Because of this I need to take a hostage. I hope she's cute. :D

                    M Offline
                    M Offline
                    Maximilien
                    wrote on last edited by
                    #9

                    MadGerbil wrote:

                    If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement.

                    it's not a secure password because you will not be able to remember it and you will write it down on a post-it or copy it on a regular text file on your desktop; or you click on the "I forgot my password" button. Anyway, agreed. I hate when I have to change passwords.

                    I'd rather be phishing!

                    M 1 Reply Last reply
                    0
                    • Mike HankeyM Mike Hankey

                      MadGerbil wrote:

                      Because of this I need to take a hostage.

                      If you have foul play in mind, I have a list! :)

                      I'm not sure how many cookies it makes to be happy, but so far it's not 27. JaxCoder.com

                      W Offline
                      W Offline
                      W Balboos GHB
                      wrote on last edited by
                      #10

                      Mike Hankey wrote:

                      I have a list!

                      By any chance, is Mike short for Mikado [^] ?

                      Ravings en masse^

                      "The difference between genius and stupidity is that genius has its limits." - Albert Einstein

                      "If you are searching for perfection in others, then you seek disappointment. If you seek perfection in yourself, then you will find failure." - Balboos HaGadol Mar 2010

                      1 Reply Last reply
                      0
                      • M Maximilien

                        MadGerbil wrote:

                        If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement.

                        it's not a secure password because you will not be able to remember it and you will write it down on a post-it or copy it on a regular text file on your desktop; or you click on the "I forgot my password" button. Anyway, agreed. I hate when I have to change passwords.

                        I'd rather be phishing!

                        M Offline
                        M Offline
                        MadGerbil
                        wrote on last edited by
                        #11

                        Every place I've seen this password policy in place I've also seen sticky notes with passwords written on them stuck to the monitors of the user's computers.

                        1 Reply Last reply
                        0
                        • S Slacker007

                          MadGerbil wrote:

                          If you write a password management system and force people to change passwords every 30 days

                          this is because if your password is compromised and I have it, then I have only 30 days to use it, before I can't anymore. Not so great for you and the company during those 30 days, but it is better than nothing, I guess. It is a valid level of security. You should be more than glad they don't make you change your password every week. And no, they are not bad people for doing this. No more as bad as the doctor who tells you to quit smoking. I agree it is frustrating, very much so.

                          M Offline
                          M Offline
                          MadGerbil
                          wrote on last edited by
                          #12

                          Slacker007 wrote:

                          this is because if your password is compromised and I have it, then I have only 30 days to use it, before I can't anymore. Not so great for you and the company during those 30 days, but it is better than nothing, I guess.

                          What the experts say: Time for Password Expiration to Die | SANS Security Awareness[^]

                          1 Reply Last reply
                          0
                          • S Slacker007

                            MadGerbil wrote:

                            If you write a password management system and force people to change passwords every 30 days

                            this is because if your password is compromised and I have it, then I have only 30 days to use it, before I can't anymore. Not so great for you and the company during those 30 days, but it is better than nothing, I guess. It is a valid level of security. You should be more than glad they don't make you change your password every week. And no, they are not bad people for doing this. No more as bad as the doctor who tells you to quit smoking. I agree it is frustrating, very much so.

                            G Offline
                            G Offline
                            GuyThiebaut
                            wrote on last edited by
                            #13

                            The problem with systems that force people to regularly change passwords is that people have a habit of simply incrementing a number at the end of a password. So the chances are that if I know your password, I can just try incrementing the number at the end until I get your current password which has probably just been incremented by one.

                            “That which can be asserted without evidence, can be dismissed without evidence.”

                            ― Christopher Hitchens

                            1 Reply Last reply
                            0
                            • M MadGerbil

                              My credit union forced me to change my password but won't let me use a previous password. I don't know why I get irrationally angry over this - I guess I feel passwords are kind of personal and telling me that I cannot use an old one doesn't improve security at all and seems invasive. If I write insecure passwords changing guest1 to guest2 isn't an improvement. If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement. There is more B.S. superstition around password management than I can handle. One of the most boogered things in all of IT are password management systems. If you write a password management system and force people to change passwords every 30 days YOU ARE A BAD PERSON IN REAL LIFE. Because of this I need to take a hostage. I hope she's cute. :D

                              A Offline
                              A Offline
                              Amarnath S
                              wrote on last edited by
                              #14

                              This means they are storing all your previous passwords. Do they guarantee you that their password storage is never going to be compormised?

                              M Richard DeemingR Kornfeld Eliyahu PeterK U B 5 Replies Last reply
                              0
                              • A Amarnath S

                                This means they are storing all your previous passwords. Do they guarantee you that their password storage is never going to be compormised?

                                M Offline
                                M Offline
                                MadGerbil
                                wrote on last edited by
                                #15

                                Exactly. If they get compromised I think they should cover every other system of mine that gets compromised. Slap a lawsuit on them for that, make them pay for damages, and maybe they'll get rational.

                                1 Reply Last reply
                                0
                                • A Amarnath S

                                  This means they are storing all your previous passwords. Do they guarantee you that their password storage is never going to be compormised?

                                  Richard DeemingR Offline
                                  Richard DeemingR Offline
                                  Richard Deeming
                                  wrote on last edited by
                                  #16

                                  Hopefully a salted hash of your previous passwords. But given some of the code that keeps cropping up in QA, I wouldn't guarantee it.


                                  "These people looked deep within my soul and assigned me a number based on the order in which I joined." - Homer

                                  "These people looked deep within my soul and assigned me a number based on the order in which I joined" - Homer

                                  A 1 Reply Last reply
                                  0
                                  • A Amarnath S

                                    This means they are storing all your previous passwords. Do they guarantee you that their password storage is never going to be compormised?

                                    Kornfeld Eliyahu PeterK Offline
                                    Kornfeld Eliyahu PeterK Offline
                                    Kornfeld Eliyahu Peter
                                    wrote on last edited by
                                    #17

                                    You have no need to store the old passwords... a one-way hash will do... But if you store one-way hash what do you afraid of?

                                    "The only place where Success comes before Work is in the dictionary." Vidal Sassoon, 1928 - 2012

                                    "It never ceases to amaze me that a spacecraft launched in 1977 can be fixed remotely from Earth." ― Brian Cox

                                    OriginalGriffO 1 Reply Last reply
                                    0
                                    • Kornfeld Eliyahu PeterK Kornfeld Eliyahu Peter

                                      You have no need to store the old passwords... a one-way hash will do... But if you store one-way hash what do you afraid of?

                                      "The only place where Success comes before Work is in the dictionary." Vidal Sassoon, 1928 - 2012

                                      OriginalGriffO Offline
                                      OriginalGriffO Offline
                                      OriginalGriff
                                      wrote on last edited by
                                      #18

                                      Kornfeld Eliyahu Peter wrote:

                                      what do you afraid of?

                                      As Richard says: Go to QA and see what some idiots developers are doing in the real world ... :sigh:

                                      "I have no idea what I did, but I'm taking full credit for it." - ThisOldTony AntiTwitter: @DalekDave is now a follower!

                                      "I have no idea what I did, but I'm taking full credit for it." - ThisOldTony
                                      "Common sense is so rare these days, it should be classified as a super power" - Random T-shirt

                                      Kornfeld Eliyahu PeterK 1 Reply Last reply
                                      0
                                      • Richard DeemingR Richard Deeming

                                        Hopefully a salted hash of your previous passwords. But given some of the code that keeps cropping up in QA, I wouldn't guarantee it.


                                        "These people looked deep within my soul and assigned me a number based on the order in which I joined." - Homer

                                        A Offline
                                        A Offline
                                        Amarnath S
                                        wrote on last edited by
                                        #19

                                        Thanks. New learning today.

                                        1 Reply Last reply
                                        0
                                        • OriginalGriffO OriginalGriff

                                          Kornfeld Eliyahu Peter wrote:

                                          what do you afraid of?

                                          As Richard says: Go to QA and see what some idiots developers are doing in the real world ... :sigh:

                                          "I have no idea what I did, but I'm taking full credit for it." - ThisOldTony AntiTwitter: @DalekDave is now a follower!

                                          Kornfeld Eliyahu PeterK Offline
                                          Kornfeld Eliyahu PeterK Offline
                                          Kornfeld Eliyahu Peter
                                          wrote on last edited by
                                          #20

                                          But of course... only speaking in theory... (that's the reason that I try to avoid opening accounts on any site, and using google's login if I can)

                                          "The only place where Success comes before Work is in the dictionary." Vidal Sassoon, 1928 - 2012

                                          "It never ceases to amaze me that a spacecraft launched in 1977 can be fixed remotely from Earth." ― Brian Cox

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups